Legislation

Cybersecurity Act (NIS2) incident reporting procedure: the step-by-step plan as a download

Required

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

You might trip while running; every organization experiences that sooner or later. The only question is whether you know where the nearest first-aid station is and whether you have a bandage on hand for the initial moment. For a cyber incident, having that "bandage on hand" means having an incident reporting procedure: a fixed step-by-step plan you can grab the moment things go wrong, rather than having to figure it out on the fly.

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

This article was last updated on
03.09.2026
Written by
Mathijs
Oppelaar
Operational Manager & Partner

Sidenote: this procedure is currently only available in Dutch.

What is included in the NIS2 incident reporting procedure?

The procedure covers the entire process: from the first sign that something is wrong, through classification (is this a significant incident or not), external reporting to your sectoral response team (CSIRT) and the competent supervisory authority, to the internal evaluation after the incident has been resolved. Each step specifies who is responsible, so you don't have to figure that out during an actual incident.

What is a significant incident under NIS2?

Not every disruption requires reporting. An incident is significant if it causes, or is likely to cause, a serious disruption of your services or financial damage to your own organization. It can also involve an incident that causes, or is likely to cause, significant material or non-material damage to other organizations or individuals. The exact thresholds vary by sector. For managed service providers and managed security service providers (MSPs and MSSPs), these have already been defined in concrete figures: an incident is considered significant if, for example, a service is completely unavailable for more than 30 minutes, or if availability is limited for more than 5% of EU users for more than an hour.

The three NIS2 reporting deadlines in brief

From the moment your organization becomes aware of a significant incident, three fixed deadlines apply: 24 hours for an early warning, 72 hours for an initial assessment of the severity and impact, and one month for the final report. All these reports go to the same address: your sectoral CSIRT and the supervisory authority responsible for your sector. If you want to go through the deadlines in detail, including exactly what must be in each report and the consequences of missing a deadline, read the article on reporting deadlines.

Who reports to the CSIRT and who is on the incident response team?

The report itself goes to your sectoral CSIRT, which supports you in the resolution process, and to the competent supervisory authority. Within your own organization, it usually takes more than one person to get this done on time: someone to determine that it is a significant incident, someone to actually submit the report, an incident response team to handle the technical resolution, and someone to document what happened and what was learned afterward. The incident reporting procedure assigns these roles so that everyone knows what is expected of them in advance.

What can you do about it now?

 

  1. You must register your organization in advance via MijnNCSC. This requires eHerkenning at level EH2+ plus authorization, which is not something you can arrange during an incident.
  2. Determine who within your organization is authorized to decide that an event is a significant incident, as that moment starts the clock for all three deadlines.
  3. Download the incident reporting procedure and walk through it with your team before you have to rely on it during a real incident.

 

This way, when you trip, you won't have to look for the route, because you'll already have it with you.

Want to know more about NIS2 and the Cyber Security Act?

Do you want to know if your organization falls under the Cyber Security Act and what else is expected of you? Schedule a no-obligation, free consultation.

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

How many people participate?

Request now

Thanks!
Oops! The form could not be submitted. Please try again.

More resources

Join our team

Employee Spotlight: from consultant to marketing manager

by
Jurre
Blog
Legislation

What is the difference between NIS and NIS2?

by
Mathijs
Kennisartikel
NIS2

Download our NIS2 checklist!

by
Ruben
Download